A method and system for identity authentication against identity spoofing attacks

By generating key pairs using elliptic curves and dynamically scheduling resources using AI models, this approach addresses the issues of identity forgery attacks and insufficient RSU computing resources in IoT vehicles, enabling efficient and reliable cross-domain authentication and ensuring low-latency communication and data trustworthiness.

CN120750593BActive Publication Date: 2025-12-09北京国瑞数智技术有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510964427.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-12-09
Estimated Expiration
2045-07-14

AI Technical Summary

Technical Problem

Existing technologies cannot effectively defend against identity spoofing attacks on IoT vehicles, and roadside units (RSUs) lack sufficient computing resources in high-user-density scenarios, failing to meet low-latency requirements.

Method used

Elliptic curve key pair generation is adopted, and AI model is used to schedule resources in real time. By preloading factors to RSU, pseudonym generation parameter calculation tasks are dynamically allocated, and identity certificates are verified using the main chain-slave chain collaborative architecture to achieve cross-domain authentication.

Benefits of technology

Effectively identify and prevent identity forgery attacks, optimize RSU computing resource burden, ensure low-latency communication, and improve the credibility and integrity of authentication data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750593B_ABST
    Figure CN120750593B_ABST
Patent Text Reader

Abstract

The application provides an identity authentication method and system resisting identity spoofing attack, which is used for guaranteeing the security of cross-domain communication. The method firstly carries out system initialization, and generates a key pair for an entity based on an elliptic curve. When a user registers in a domain, an authentication center generates a key pair, encryption parameters and an identity certificate and stores them in a from chain. A key generation center (KGC) pre-generates a factor containing a private key and pre-loads it to a roadside unit (RSU). When the user initiates a pseudonym generation request, the RSU verifies and forwards the request to a nearby base station; the base station uses an AI model to predict the resource usage state, and dynamically assigns a service base station to calculate the pseudonym generation parameters in real time. After the user obtains the parameters, the user generates the own pseudonym, verification parameters and a key pair, and uses the pseudonym key to generate a unique signature, encrypts the message and sends it. After the receiver verifies the validity of the message, the receiver forwards the verification request to the base station through the RSU, and also dynamically assigns a service base station to verify the legality of the pseudonym based on the AI strategy, and queries and verifies the user's identity certificate by carrying address information across the chain (from chain / main chain cooperation). The application can effectively identify malicious vehicles that fake pseudonyms, and use AI to realize dynamic scheduling of resources, and meet the low delay requirement.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to an identity authentication method and system resisting identity spoofing attack. BACKGROUND

[0002] In order to ensure the identity security of Internet of Vehicles in the cross-domain communication process, the prior art proposes an anonymous authentication scheme for hiding the real identity, and only the trusted authority can retrieve the real identity from the pseudonym. At the same time, the prior art also introduces a pseudonym allocation mechanism assisted by a roadside unit (RSU) proxy. However, these existing anonymous mechanisms do not consider the identity spoofing attack of the vehicle, and through the spoofing of the pseudonym and the corresponding key, a malicious vehicle can initiate various attacks on the Internet of Vehicles. The existing anonymous mechanism cannot identify and locate the above-mentioned malicious vehicle.

[0003] Moreover, the existing roadside unit RSU needs more and more computing resources, and when there are too many users near a certain RSU, the RSU will not be able to meet the low-latency requirement of the users. It is necessary to consider combining the AI large model to dynamically formulate a strategy in real time.

[0004] Therefore, there is an urgent need for a targeted identity authentication method and system resisting identity spoofing attack. SUMMARY

[0005] The purpose of the present application is to provide an identity authentication method and system resisting identity spoofing attack, which overcomes the problem that the prior art cannot defend against identity spoofing attack and meets the requirement of real-time dynamic scheduling of resources.

[0006] In a first aspect, the present application provides an identity authentication method resisting identity spoofing attack, which comprises the following steps:

[0007] System initialization, including generating a key pair for each entity through an elliptic curve;

[0008] The user registers an identity in the domain, and the authentication center generates a corresponding key pair, encryption parameter and identity certificate for the user, and uploads them to the storage on the chain;

[0009] Returning the address information from the chain;

[0010] Generating a preloaded factor containing a private key in the key generation center KGC, and the batch of factors are preloaded on the roadside unit RSU, which is used for subsequent calculation of the generation parameter of the pseudonym;

[0011] When the user starts a pseudonym generation request to the nearby RSU, the RSU verifies the legality of the request, forwards it to the nearby base station, and the base station predicts the resource usage state of the service base station and the adjacent station through an AI model, formulates a strategy, and assigns the service base station to calculate the generation parameter of the pseudonym in real time;

[0012] After the user receives the pseudonym generation parameters, the user generates his own pseudonym, verification parameters and corresponding key pair;

[0013] The user calculates a unique signature using the pseudonym and key pair, and encrypts the message using the signature;

[0014] When the user requests communication, a message package is sent to the recipient, which carries address information;

[0015] The recipient receives the message package, verifies its validity, and sends the message package to the nearby RSU, which is forwarded to the nearby base station, and the service base station is assigned in real time according to the strategy to verify the legitimacy of the user pseudonym;

[0016] The recipient submits a pseudonym request to the nearby RSU, which carries address information, queries whether the address information is contained in the chain, and performs cross-domain inquiry for data verification;

[0017] If the address information is contained in the chain, the identity certificate is returned, otherwise the address information is sent to the main chain for assistance to complete the query;

[0018] The identity certificate is returned to the recipient from the chain;

[0019] The recipient verifies the signature of the user's identity, and if the user does not use the pseudonym generation parameters, the verification fails.

[0020] In a second aspect, the present application provides an identity authentication system against identity spoofing attacks, comprising:

[0021] An initialization module for system initialization, including generating a key pair for each entity through an elliptic curve;

[0022] An authentication center for user registration of identity in the domain, generating corresponding key pairs, encryption parameters and identity certificates for the user, and uploading to the storage on the chain; receiving address information returned from the chain;

[0023] A key generation center KGC for generating preloaded factors containing private keys, and the batch of factors are preloaded on the roadside unit RSU for subsequent calculation of pseudonym generation parameters;

[0024] A roadside unit RSU for receiving user-initiated pseudonym generation requests, verifying the legitimacy of the request, and forwarding it to the nearby base station;

[0025] A base station for predicting the resource usage state of the service base station and neighboring stations through an AI model, formulating a strategy, and assigning the service base station to calculate the pseudonym generation parameters in real time;

[0026] The user is configured to send a pseudonym generation request to a nearby RSU, and after receiving the pseudonym generation parameters, generate a pseudonym, a verification parameter and a corresponding key pair of the user, calculate a unique signature using the pseudonym and the key pair, and encrypt a message using the signature; when the user requests communication, send a message package to a receiver, the message package carrying address information;

[0027] The receiver is configured to receive the message package, verify the validity of the message package, and send the message package to a nearby RSU, which forwards the message package to a nearby base station, and according to a strategy, assign a service base station to verify the legitimacy of the pseudonym of the user in real time; submit a pseudonym request to the nearby RSU, the pseudonym request carrying address information, query whether a chain contains the address information, and perform cross-domain inquiry for data verification; verify the signature of the user identity, and if the user does not use the pseudonym generation parameter, the verification fails.

[0028] The chain is configured to determine whether the address information is contained, and if yes, return an identity certificate, otherwise, send the address information to a main chain to assist in completing the query; and return the identity certificate to the receiver.

[0029] In a third aspect, the present application provides an identity authentication system resisting identity spoofing attacks, the system comprising a processor and a memory:

[0030] The memory is configured to store program code and transmit the program code to the processor;

[0031] The processor is configured to execute the method according to the instructions in the program code.

[0032] In a fourth aspect, the present application provides a computer readable storage medium, the computer readable storage medium being configured to store program code, the program code being configured to be executed by a processor to implement the method according to any one of the first aspect.

[0033] Advantages

[0034] The application provides an identity authentication method and system against identity spoofing attack, which first carries out system initialization, generates a key pair for an entity based on an elliptic curve. When a user registers in a domain, an authentication center generates a key pair, encryption parameters and an identity certificate and stores them in a slave chain. A key generation center (KGC) pre-generates a factor containing a private key and preloads it to a roadside unit (RSU). When the user initiates a pseudonym generation request, the RSU verifies and forwards the request to a nearby base station; the base station predicts the resource usage state by using an AI model, dynamically assigns a service base station to calculate the pseudonym generation parameters in real time. After the user obtains the parameters, the user generates the user's own pseudonym, verification parameters and key pair, and encrypts the message by using the unique signature generated by the pseudonym key and then sends the message. After the receiver verifies the validity of the message, the receiver forwards the verification request to the base station through the RSU, and the base station verifies the legality of the pseudonym based on the AI strategy and dynamically assigns a service base station, and queries and verifies the user's identity certificate by carrying address information across the chain (slave chain / main chain cooperation).

[0035] The method and system of the application have the following advantages and effects:

[0036] 1. Effectively resist identity spoofing attack: the application designs a computer mechanism based on preloaded factor and pseudonym generation parameters, which requires users to use the legal parameters generated by the system to construct pseudonyms and keys. The receiver can effectively identify the pseudonyms and keys generated without using legal parameters (i.e. fake) by querying the certificate across the chain and verifying the signature when verifying the identity, so as to accurately locate and prevent identity spoofing attacks of malicious vehicles, and solve the key defect that the prior art cannot identify fake identity.

[0037] 2. Realize efficient and reliable cross-domain authentication: the main chain-slave chain cooperative architecture is used to store and query the user's identity certificate (stored in the slave chain and assisted in cross-domain query in the main chain), and combined with digital signature verification, the verifiability and non-repudiation of the identity authentication data in cross-domain communication are ensured.

[0038] 3. Significantly optimize the RSU computing resource burden and improve the efficiency: the high-computing tasks such as pseudonym generation parameter calculation and pseudonym legality verification originally borne by the RSU are dynamically assigned to the base station with stronger computing capacity for processing. In particular, the optimal service base station (in the domain or the neighborhood) is predicted and scheduled in real time by using an AI model, which greatly relieves the resource bottleneck problem of a single RSU in a user-intensive scenario.

[0039] 4. AI-driven dynamic resource scheduling, guaranteeing low latency demand: an AI large model is introduced to predict the resource usage state of the base station group (service base station and adjacent station) in real time, and a strategy is made to dynamically assign the computing task according to the prediction, so as to realize the global optimization and real-time distribution of resources. This makes the system still meet the strict requirement of low latency of Internet of Things vehicle communication under high concurrency request.

[0040] 5. Enhance data verification credibility: cross-chain query mechanism (from chain -> main chain -> slave chain) ensures that even across domains, the original identity certificate of the user can be efficiently and reliably obtained and verified, improving the data credibility and integrity of the entire identity authentication process. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.

[0042] Figure 1 The flowchart of the present application;

[0043] Figure 2 The system architecture diagram of the present application. DETAILED DESCRIPTION

[0044] The preferred embodiments of the present application will be described in detail below with reference to the drawings, so that the advantages and features of the present application can be more easily understood by those skilled in the art, and the protection scope of the present application can be more clearly defined.

[0045] There are two ways for the existing technology to forge a pseudonym: first, after malicious vehicles complete registration in the domain, they do not send a pseudonym request to the system, but forge an illegal pseudonym to communicate with surrounding entities. The generation of this illegal pseudonym is not verified and authorized by the system pseudonym mechanism.

[0046] Second, a malicious vehicle has initiated a pseudonym generation request to the system, obtained the authorization parameters for pseudonym generation, and generated a legal pseudonym according to the system's rules. However, in the actual communication process, it does not use the legal pseudonym, but forges another pseudonym through the authorization parameters, packages the other pseudonym and the authorization parameters, and initiates an attack, making it impossible for the system to locate its real identity.

[0047] However, the traditional single-chain blockchain architecture cannot meet the cross-domain needs of the Internet of Vehicles. The data of the vehicle domain needs to be frequently read and written in the blockchain, and each identity verification transaction must be verified by consensus before being written.

[0048] Moreover, the existing roadside unit RSU requires more and more computing resources, and when there are too many users near a certain RSU, the RSU will not be able to meet the user's low-latency requirements. It is necessary to consider combining AI large models to dynamically formulate strategies in real time.

[0049] The identity authentication method against identity forgery attacks provided by the present application, the method comprises:

[0050] System initialization, including generating key pairs for each entity through elliptic curve;

[0051] User registers identity in domain, authentication center generates corresponding key pair, encryption parameter and identity certificate for user, and uploads to storage from chain;

[0052] Return address information from chain;

[0053] Generate preloaded factor containing private key in key generation center KGC, and batch of factors are preloaded on roadside unit RSU for subsequent calculation of pseudonym generation parameter;

[0054] When user starts a pseudonym generation request to nearby RSU, RSU verifies the legality of the request, forwards it to nearby base station, and base station predicts resource usage state of service base station and adjacent station through AI model, formulates strategy, and assigns service base station to calculate pseudonym generation parameter in real time;

[0055] User receives pseudonym generation parameter, generates own pseudonym, verification parameter and corresponding key pair;

[0056] User calculates unique signature using pseudonym and key pair, and encrypts message using signature;

[0057] When user requests communication, send message package to receiver, which carries address information;

[0058] Receiver receives message package, verifies its validity, sends message package to nearby RSU, which forwards it to nearby base station, and base station verifies legality of user pseudonym according to strategy in real time;

[0059] Receiver submits pseudonym request to nearby RSU, which carries address information, queries whether address information is contained in from chain, and performs cross-domain query for data verification;

[0060] If from chain contains address information, return identity certificate, otherwise send address information to main chain, which assists to complete query;

[0061] From chain returns identity certificate to receiver;

[0062] Receiver verifies signature of user identity, and if user does not use pseudonym generation parameter, verification fails.

[0063] The malicious user in the above process cannot pass the signature verification because the legitimate pseudonym generation parameter is not used. The related calculation of the pseudonym generation parameter increases the workload of the RSU. By using distributed base stations and service base stations, the computing burden of the RSU can be reduced, the cost can be reduced, the computing capacity of the base station can be fully utilized, the AI model can be deployed in the base station, the strategy can be predicted in real time, and the resources can be utilized more scientifically.

[0064] In some preferred embodiments, the user includes a first user and a second user, the first user and the second user are registered in different domains respectively, the identity certificate of each is stored in two independent sub-chains, namely a first sub-chain and a second sub-chain, and two different certificate storage account addresses are obtained.

[0065] In some preferred embodiments, the first user establishes a connection with a trusted entity in the domain where the first user is located, that is, a first sub-chain, and the first user queries whether the identity certificate of the corresponding user exists through the account address of the second user, if the identity certificate exists, the first user is directly returned to the trusted entity for identity verification, if the identity certificate of the second user does not exist in the first sub-chain, the first sub-chain submits a request to the corresponding node in the main chain, and the main chain queries the data information of the account address in the second sub-chain.

[0066] In some preferred embodiments, when the account address is queried from the second sub-chain, the main chain sends a data response received from the second sub-chain to the first sub-chain, and the trusted entity of the first sub-chain uses the identity certificate in the data to perform related authentication, if the authentication is passed, the first user and the second user in different domains are allowed to communicate.

[0067] The user can be a vehicle, and the so-called trusted entity can be a corresponding node of the sub-chain, the first user or the second user can be a sender or a receiver.

[0068] Figure 2 The architecture diagram of the identity authentication system against identity forgery attack provided in the present application, the system comprises:

[0069] An initialization module for system initialization, including generating a key pair for each entity through an elliptic curve;

[0070] An authentication center for user registration in a domain, generating a corresponding key pair, encryption parameter and identity certificate for the user, and uploading to a sub-chain for storage; receiving address information returned by the sub-chain;

[0071] A key generation center KGC for generating a preloaded factor containing a private key, and a batch of factors are preloaded on a roadside unit RSU for subsequent calculation of pseudonym generation parameters;

[0072] A roadside unit (RSU) configured to receive a pseudonym generation request initiated by a user, verify the legitimacy of the request, and forward the request to a nearby base station;

[0073] A base station configured to predict resource usage states of a serving base station and neighboring base stations by an AI model, formulate a strategy, and assign the serving base station to calculate pseudonym generation parameters in real time;

[0074] A user configured to initiate a pseudonym generation request to a nearby RSU, generate a pseudonym, a verification parameter, and a corresponding key pair after receiving the pseudonym generation parameters, calculate a unique signature using the pseudonym and the key pair, and encrypt a message using the signature, and send a message package to a receiver when the user requests communication, the message package carrying address information.

[0075] A receiver configured to receive a message package, verify the validity of the message package, and send the message package to a nearby RSU, which forwards the message package to a nearby base station, which verifies the legitimacy of the user's pseudonym according to a strategy, and submit a pseudonym request to a nearby RSU, which queries whether a blockchain contains address information, performs cross-domain queries for data verification, and verifies a user's signature to determine whether the user has used a pseudonym generation parameter.

[0076] A blockchain configured to determine whether it contains address information, and if so, return an identity certificate, or if not, send the address information to a main chain to assist in completing the query, and return the identity certificate to the receiver.

[0077] The present application provides an identity authentication system that resists identity spoofing attacks, the system comprising a processor and a memory:

[0078] The memory is configured to store program code and transmit the program code to the processor;

[0079] The processor is configured to execute the method according to the instructions in the program code.

[0080] The present application provides a computer-readable storage medium for storing program code, the program code being used to implement the method according to any one of the embodiments of the first aspect.

[0081] In specific implementations, the present application also provides a computer storage medium, which can store a program that, when executed, can include some or all steps in various embodiments of the present application. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0082] Those skilled in the art can clearly understand that the technical solution in the embodiments of the present application can be realized by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution in the embodiments of the present application can be embodied in a software product form, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a plurality of instructions to cause a computer device (which can be a personal computer, a server, or a network device, and the like) to execute the methods described in the various embodiments or some parts of the embodiments of the present application.

[0083] The same or similar parts among the various embodiments of the present application can be referred to each other. In particular, for the embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.

[0084] The above-described embodiments of the present application do not constitute a limitation on the protection scope of the present application.

Claims

1. An identity authentication method against identity spoofing attack, characterized by, The method comprises: System initialization, including generating a key pair for each entity through an elliptic curve; A user registers an identity in a domain, and an authentication center generates a corresponding key pair, encryption parameters and an identity certificate for the user, and uploads to storage from a chain; Return address information from the chain; Generating a preloaded factor containing a private key in a key generation center KGC, and the batch of factors are preloaded on a roadside unit RSU for subsequent calculation of pseudonym generation parameters; When a user initiates a pseudonym generation request to a nearby RSU, the RSU verifies the legality of the request, forwards it to a nearby base station, and the base station predicts the resource usage state of the serving base station and neighboring stations through an AI model, formulates a strategy, and assigns the serving base station to calculate the pseudonym generation parameters in real time; After the user receives the pseudonym generation parameters, the user generates own pseudonym, verification parameters and a corresponding key pair; The user calculates a unique signature using the pseudonym and the key pair, and encrypts a message using the signature; When the user requests communication, a message package is sent to the receiver, and the message package carries address information; After the receiver receives the message package, the receiver sends the message package to a nearby RSU after verifying its validity, and the RSU forwards the message package to a nearby base station, which verifies the legality of the user pseudonym according to the strategy and assigns the serving base station in real time; The receiver submits a pseudonym request to the nearby RSU, which carries address information, queries whether the address information is contained in the chain, and performs cross-domain inquiry for data verification; If the address information is contained in the chain, the identity certificate is returned, otherwise the address information is sent to the main chain, and the main chain assists to complete the query; The chain returns the identity certificate to the receiver; The receiver verifies the signature of the user's identity, and if the user does not use the pseudonym generation parameters, the verification fails.

2. The method of claim 1, wherein: The user includes a first user and a second user, and the first user and the second user are registered in different domains respectively, and the identity certificates of the first user and the second user are stored in two independent chains, namely a first chain and a second chain, to obtain two different certificate storage account addresses.

3. The method of claim 2, wherein: The first user establishes a connection with a trusted entity in the domain where the first user is located, i.e. the first chain, and the first user queries whether the identity certificate of the corresponding user exists through the account address of the second user, and if the identity certificate exists, the first chain returns to the trusted entity for identity authentication, and if the identity certificate of the second user does not exist in the first chain, the first chain submits a request to the corresponding node in the main chain, and queries the data information of the account address in the second chain in the main chain.

4. The method of claim 2, wherein: When the account address is queried from the second chain, the main chain sends the data received from the second chain to the first chain, and the trusted entity of the first chain uses the identity certificate in the data to perform related authentication, and if the authentication passes, the first user and the second user in different domains are allowed to communicate.

5. An identity authentication system against identity spoofing attack, characterized by, The system comprises: An initialization module for system initialization, including generating a key pair for each entity through an elliptic curve; An authentication center for a user to register an identity in a domain, generating a corresponding key pair, encryption parameters and an identity certificate for the user, and uploading to storage from a chain; and receiving address information returned from the chain; A key generation center KGC is configured to generate preloaded factors containing private keys, and the batch of factors are preloaded to a roadside unit RSU for subsequent calculation of pseudonym generation parameters. The roadside unit RSU is configured to receive a user-initiated pseudonym generation request, verify the legality of the request, and forward it to a nearby base station. The base station is configured to predict the resource usage state of the serving base station and neighboring stations through an AI model, develop a strategy, and assign the serving base station to calculate the pseudonym generation parameters in real time. The user is configured to initiate a pseudonym generation request to a nearby RSU, generate his own pseudonym, verification parameters, and corresponding key pair after receiving the pseudonym generation parameters, calculate a unique signature using the pseudonym and key pair, and encrypt the message using the signature; when the user requests communication, send a message package to the recipient, which carries address information. The recipient is configured to receive the message package, verify its validity, and send the message package to a nearby RSU, which forwards it to a nearby base station to verify the legality of the user's pseudonym according to the real-time assignment strategy of the serving base station; submit a pseudonym request to a nearby RSU, which carries address information, query whether the address information is contained in the chain, and perform cross-domain inquiry for data verification; verify the user's signature, and if the user has not used the pseudonym generation parameters, the verification fails. The chain is configured to determine whether the address information is contained, and if so, return an identity certificate, otherwise send the address information to the main chain for assistance in completing the query; and return the identity certificate to the recipient from the chain.

6. An identity authentication system against identity spoofing attacks, characterized by, The system includes a processor and a memory: The memory is configured to store program code and transmit the program code to the processor; The processor is configured to execute instructions in the program code to implement the method of any one of claims 1-4.

7. A computer readable storage medium characterized by The computer-readable storage medium is configured to store program code for being executed by the processor to implement the method of any one of claims 1-4.

Citation Information

Patent Citations

  • Alliance chain cross-chain-oriented identity authentication method

    CN117335958A

  • Certificateless identity authentication method based on block chain and related device

    CN119766448A